• CVE-2025-8851

发布时间: 2025年8月15日

修改时间: 2025年9月5日

概要

A vulnerability was found in LibTIFF up to 4.5.1 (Image Processing Software). It has been rated as critical.Using CWE to declare the problem leads to CWE-121. A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).Impacted is confidentiality, integrity, and availability.Applying the patch 8a7a48d7a645992ca83062b3a1873c951661e2b3 is able to eliminate this problem. The bugfix is ready for download at gitlab.com.

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Local
CVSS评分 N/A 5.3
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Integrity Low
User Interaction None
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2837 libtiff security update 2025年9月15日
KylinSec-SA-2025-2870 libtiff security update 2025年9月15日

影响产品

产品 状态
KY3.4-5A libtiff Fixed
KY3.5.3 libtiff Fixed
KY3.5.2 libtiff Fixed